NEW YORK STATE SECURITY BREACH REPORTING FORM 
Pursuant to the Information Security Breach and Notification Act 
(General Business Law §899-aa) 


Namgjnd address of Enti ty that owns or licenses the computerized data that was subject to the breach : 

McDermott Will & Emery LLP_ 

Street Address: 227 West Monroe Street_ 

City: Chicago_ State: IL_ Zip Code: 60606_ 


Submitted by : Ann I. Killilea, Esq._ Title: Privacy Officer_ Dated: 2/27/15. 

Firm Name (if other than entity): ___ 

Telephone: _617-535-4000_ Email: akillilea@mwe.com_ 

Relationship to Entity whose information was compromised: 


Type of Organization (please select one): ( ] Governmental Entity in New York State; ( ] Other Governmental Entity; 
( 1 Educational; [ [Health Care; ( [Financial Services; [x ]Other Commercial; or [ ]Not-for-profit. 


Number of Persons Affected : SEE ATTACHED 

Total (Including NYS residents):_ NYS Residents:_ 

If the number of NYS residents exceeds 5,000, have the consumer reporting agencies been notified? [ ] Yes f ] No 


Pates :- Breach Occurred: 12/10/14 - Breach Discovered:-1/29/1 5 - Consumer Notification: see attached 


Peamptipn pf Breach (please select all that apply): 

[ ]Loss or theft of device or media (e.g., computer, laptop, external hard drive, thumb drive, CD, tape); 

[ [Internal system breach; [ [Insider wrongdoing; ( x [External system breach (e.g., hacking); 

( [Inadvertent disclosure; [ [Other specify):_^___ 

Information Acquired : Name or other personal identifier in combination with (please select all that apply): 

[ [Social Security Number 

[ [Driver’s license number or non-driver identification card number 

| [Financial account number or credit or debit card number, in combination with the security code, access code, 
password, or PIN for the account 


Manner of Notification to Affected Persons - ATTACH A COPY OF THE TEMPLATE OF THE NOTICE TO 
AFFECTED NYS RESIDENTS: 

[ } Written { ] Electronic [ ] Telephone [ J Substitute notice 

List dates of any previous (within 12 months) breach notifications: __ 

M^Ufy_Theft P ro tec tip n^e.ryi.c.g_Qffg.r£d: [ [Yes [ J No 


Duration:_ 

Brief Description of Service: 


Provider: 












Melissa O'Neill 


rncw 


From: 

Sent: 

To: 

Subject: 


Katherine Milgram 

Wednesday, April 01, 2015 11:48 AM 
Melissa O'Neill 

RE Bureau of Securities Data Breach Notification 



Katherine 


From: Carney, Carrie 

Sent: Sunday, March 22, 2015 9:30 AM _ 

To: 'Cynthia.Drinkwater@alaska.gov'; Taren.Langford@azag.gov'; 'Jeff.Steele@doj.ca.gov'; 'Jay.Simonson@state.co.us; 
'michele.lucan@ct.gov'; 'Patrice.Malloy@myfloridalegal.com'; 'dwalsh@law.ga.gov'; 'mvanhise@atg.state.il.us'; 
'Stephanie.Kindred@atg.in.gov'; 'Rick.Evans@ky.gov'; 'sara.cable@state.ma.us'; 'kfoster@oag.state.md.us'; Moylan, 
Christina; 'GabrielseM@michigan.gov'; 'david.cullen@ag.state.mn.us'; 'Nathan.Aquino@ago.mo.gov'; 
'medwa@ago.state.ms.us'; 'Kdarruda@ncdoj.gov'; 'Abigaii.stempson@nebraska.gov'; 'James.Boffetti@doj.nh.gov'; 

'Alina.Wells@dol.lps.state.nj.us'; 'BArmstrong@ag.nv.gov'; 'Eric.Gooding@ohioattorneygeneral.gov'; 
'nditomo@attorneygeneral.gov'; 'fperkins@riag.ri.gov'; 'Cynthia.Kinser@ag.tn.gov'; 

'Esther.Chavez@texasattorneygeneral.gov'; 'Jbuckner@utah.gov'; 'SFishel@oag.state.va.us'; 'ryan.kriger@state.vt.us; 
'paulas@atg.wa.gov'; 'CooleyGJ@DOJ.STATE.WI.US'; 'chad.johnson@ag.ny.gov'; 'slynch@scag.gov' 

Cc: Shaw, Judith M; Black, Karla 
Subject: notice of data breach 

Dear Members of the NAAG Privacy Working Group: 

I am writing this message on behalf of my client, the Maine Office of Securities. As you are all probably aware, a data 
security incident occurred between August, 2012 and February 27, 2015 that may have involved the personal 
information for some residents of your state who are licensed in Maine as investment adviser representatives or broker- 
dealer agents. 

The breach involved personal information provided to the Financial Industry Regulatory Authority ("FINRA") as part of a 
Disclosure Reporting Page. That information was included unintentionally in a report called the State Data Download 
which the Maine Office of Securities ("the Office") began using beginning in August, 2012. The Office provided the State 
Data Download report to third parties who requested information from the Office about investment adviser 
representatives and broker-dealer agents licensed in the state of Maine. The Office requested that all personal 
information be withheld from the report and in fact believed that it had been withheld. However, the Office learned in 
late February that some personal information had not been withheld in the reports the Office released between 2012 
and 2015. The Office has discontinued use of the report until such time as personal information can be appropriately 
safeguarded. 

Upon discovery of the personal information in the report, the Maine Office of Securities diligently investigated the 
incident and has found no information to suggest that the personal information disclosed in the reports has been 
misused. The Maine Office of Securities is in the process of preparing to provide notification to individuals who reside in 
your state whose personal information was made vulnerable by this incident. The notices to affected individuals will 
alert them of the vulnerability of their information and encourage them to take immediate steps to protect themselves 
against possible identity theft or other misuse of their information, including contact information to obtain a free credit 
report and information on how they can request a credit fraud alert or security freeze be placed on their credit files from 
the three credit reporting agencies. 

While I have not determined that the Maine Office of Securities has a reporting obligation under your state's law, I am 
providing this notice to you as a courtesy and out of an abundance of caution. If you believe that additional notice or 
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